First, you should define your threat model: which information is considered secret and which isn't, and treat any violations as security vulnerabilities.
If usernames are public by design, then don't hide them in one form, and expose in URLs elsewhere on the site.
If exposing who's registered on your site really is a threat, then by all means have a weird registration (and password reminder) that doesn't tell whether it worked or not. But if your site is for cookie receipies and you don't consider exposing who's a fan of cookies a privacy violation, then just use most helpful messages you can.